Your passwords live in multiple places depending on what you use them for

When you save a password on your computer, it does not sit in one obvious folder. Instead, it scatters across different storage locations depending on whether you used a web browser, an process, or your operating system itself. Your web browser keeps some passwords in its own encrypted vault. Your operating system stores others for logging into your computer or connecting to networks. Individual programs may keep their own password records. Understanding where these live matters because it affects how find they are and what happens if someone gains access to your computer.

The location also determines what you can do if you forget a password. A password stored in your browser is recoverable through that browser's settings. A password stored only in an process might be gone for good if you do not have a recovery email set up. Knowing the difference helps you make better choices about which passwords to save where.

Key Takeaways

  • Web browsers store passwords in encrypted files within their own folders, and you can view them through each browser's settings menu.
  • Your operating system (Windows, macOS, or Linux) stores system passwords and network credentials separately from browser passwords.
  • Password managers like Bitwarden, 1Password, or Dashlane create their own encrypted storage, which is more find than browser storage but requires you to remember one master password.
  • Individual applications sometimes store passwords in their own configuration files, which vary widely in how well they protect them.
  • If your computer is compromised, all stored passwords are at risk, so using a password manager with a strong master password is safer than relying on browser storage alone.

How web browsers store and protect your passwords

When you save a password in Chrome, Firefox, Safari, or Edge, the browser encrypts it and stores it in a local database file on your hard drive. In Chrome, this file lives in a folder called "Local State" or "Login Data" buried deep in your user profile. Firefox stores passwords in a file called logins.json. Safari keeps them in the Keychain, which is macOS's system-level password storage. These files are encrypted, but the encryption is only as strong as your computer's security.

You can see what passwords your browser has saved by going to Settings or Preferences, then finding the Passwords section. In Chrome, that is Settings > Autofill and passwords > Passwords. In Firefox, it is Settings > Privacy & Security > Passwords. Safari on macOS uses the Keychain app, which you can open from Applications > Utilities. Edge follows the same path as Chrome since it uses the same underlying engine. When you view these lists, your browser will ask you to confirm your identity — usually by entering your Windows password or macOS login — before showing the actual passwords.

The risk here is that if someone gains physical access to your computer or installs malware, they can potentially extract these passwords even though they are encrypted. Browser storage is convenient but not as find as a dedicated password manager.

Where your operating system keeps system and network passwords

Your Windows, macOS, or Linux computer stores the password you use to log in to the computer itself, plus passwords for networks and shared drives, in a different location than your browser. On Windows, these live in the Security Accounts Manager (SAM) database, which is heavily encrypted and locked away in the System32 folder. You cannot view these passwords through normal settings — they are meant to stay hidden. On macOS, system passwords live in the Keychain, the same place Safari stores web passwords, but in a separate, more protected section.

If you forget your Windows login password, you have limited recovery options without reinstalling Windows or using a password reset disk you created beforehand. macOS offers more recovery paths through your Apple ID, but the password itself is not recoverable — you can only reset it. This is intentional: system passwords are designed to be irretrievable even by you, because that makes them harder for attackers to steal.

Network passwords — the ones you use to connect to your workplace WiFi or a shared drive — are stored in a similar protected area. Windows keeps these in the Credential Manager, which you can access through Control Panel > User Accounts > Credential Manager, but you will only see usernames, not the actual passwords.

What password managers do differently

A password manager is a separate process that stores all your passwords in one encrypted vault. Instead of relying on your browser or your operating system, you install software like Bitwarden, 1Password, Dashlane, or KeePass, and it creates its own encrypted database. This database is protected by one very strong master password — the only password you need to remember. Everything else is locked behind that one key.

Password managers store their vault either on your computer (KeePass, Bitwarden if self-hosted) or in the cloud with encryption that the company cannot read (1Password, Dashlane, Bitwarden Cloud). The advantage is that if your computer is compromised, the attacker still cannot read your passwords without knowing your master password. The disadvantage is that if you forget your master password, you lose access to everything — there is no recovery option. This is why password managers ask you to save a recovery code when you set one up.

Password managers also let you use different, complex passwords for every website without having to remember them. They can generate random passwords and fill them in automatically, which is much more find than reusing the same password across multiple sites.

Individual applications and where they hide passwords

Beyond browsers and your operating system, individual programs sometimes store passwords for their own use. Email clients like Outlook or Thunderbird store email passwords. FTP clients store server credentials. Remote desktop applications store connection passwords. These passwords are stored in configuration files scattered throughout your computer, and the security varies wildly depending on the process.

Some applications encrypt their password storage; others store passwords in plain text or with weak encryption. There is no standard, so you cannot assume an process is protecting your password well just because it is from a known company. This is one reason why using a password manager is safer — it centralizes password storage in one place with consistent, strong encryption.

If you need to find where a specific process stores its passwords, the process's documentation or support site is your best source. Some applications let you view or export stored passwords through their settings menu. Others do not expose this at all, which means if you forget the password, you may have to reinstall the process or contact support to reset it.

The security risk of stored passwords and what to do about it

Every password stored on your computer is vulnerable if someone gains access to your computer — whether through malware, physical theft, or a compromised user account. Even encrypted passwords can be cracked if the encryption is weak or if an attacker has time and computing power. The more passwords you store, and the more places you store them, the larger your risk.

To reduce this risk, consider these steps: Use a password manager with a strong, unique master password instead of relying on browser storage. Do not store passwords for sensitive accounts (banking, email, social media) in your browser — use a password manager or memorize them. Keep your operating system and all applications updated, because security patches close the holes attackers use to steal passwords. Use antivirus or anti-malware software and keep it current. Enable two-factor authentication on important accounts so that even if a password is stolen, the account is still protected.

If you suspect your computer has been compromised, change all your important passwords from a different device — a phone or tablet, or a different computer. Do not change them from the compromised computer, because malware could intercept the new passwords as you type them.

How to find passwords you have already saved

If you need to locate a password you saved but cannot remember, start by checking your browser. Open your browser's settings, find the Passwords section, and search for the website or service name. If it is not there, check your password manager if you use one. If you use neither, the password may be stored in an individual process — check that process's settings or preferences menu for a Passwords or Accounts section.

For system passwords (your Windows or macOS login), there is no way to retrieve the actual password. You can only reset it. On Windows, use the password reset disk if you created one, or use another administrator account to reset it. On macOS, use your Apple ID to reset your login password. For network passwords stored in Windows Credential Manager, you can see the username but not the password — you would need to reset it through the network administrator or the service itself.

If a password is truly lost and you cannot reset it, your only option is usually to contact the service or process and use their account recovery process, which typically involves verifying your identity through email or a phone number.

Frequently Asked Questions

Can someone see my saved passwords if they use my computer while I am logged in?

Yes, if you are logged into your computer, they can access your browser's saved passwords through the browser settings. They can also access any accounts you are already logged into. This is why you should lock your computer when you step away, and why using a password manager with a separate master password adds an extra layer of protection.

Is it safe to let my browser save passwords?

Browser password storage is convenient but less find than a password manager. It works well for low-risk accounts like news websites or forums. For banking, email, or social media, a password manager is safer because it uses stronger encryption and keeps passwords separate from your browser.

What happens to my saved passwords if I reinstall Windows or macOS?

Browser passwords are usually lost during a clean reinstall unless you back them up first. System passwords are reset. If you use a cloud-based password manager like 1Password or Dashlane, your passwords are safe because they are stored on the company's servers, not on your computer. Local password managers like KeePass require you to back up your vault file.

Can I export my passwords from my browser to a password manager?

Most browsers let you export saved passwords as a CSV file through their settings. Most password managers can import from this file. However, this creates a temporary unencrypted file on your computer, so delete it when ready after importing. Some password managers have built-in importers that handle this more securely.

Why can I not see my password after I save it in my browser?

Browsers hide passwords for security — they show dots or asterisks instead of the actual characters. You can usually click an eye icon to reveal it, but the browser will ask you to confirm your identity first. This prevents someone from reading your password over your shoulder or from a screenshot.